From nobody Tue Feb 10 00:40:07 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1570548379; cv=none; d=zoho.com; s=zohoarc; b=XN5H2N5sxFzoYQN2zkC8Ppm/NOOyTInJrFL11IOuCfIbr/5xo3TTGn+i2CknK502mkNZ1B5+03/M4WEZNuw7SpvzggGaUY3us+uj1JRpvfB/b1isFaDG6LOrjMBS/9QH/8TrYTb7OHzEelRrSG4pZrUQS2PbKzFNW7nLFBCwp7Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zoho.com; s=zohoarc; t=1570548379; h=Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=qEK4F143ev3qFWGpfCxXsILQPsLMjW8oEJOhcrgZN1M=; b=L6FbrWZOjyUu07JIH8ajM4WdEifqt2pW/RJ1g3lOSnEELn+UINMRAnyb1+Eb1gnW3p5M7VACYHg8i0eRuImEkyLodCvbTn61ucsiI4l8/5BmPu4XPpBdv6DBJziJQRnmhttVd7oDUklu8JbWgs5gJgdGbyLtYNvZBJNEvD/jOb0= ARC-Authentication-Results: i=1; mx.zoho.com; spf=pass (zoho.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 157054837983398.47914887539412; Tue, 8 Oct 2019 08:26:19 -0700 (PDT) Received: from localhost ([::1]:57396 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iHrNK-00040d-K9 for importer@patchew.org; Tue, 08 Oct 2019 11:26:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:58358) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iHrHB-00074p-Ai for qemu-devel@nongnu.org; Tue, 08 Oct 2019 11:19:51 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1iHrH8-0000Xe-Uf for qemu-devel@nongnu.org; Tue, 08 Oct 2019 11:19:49 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]:6972 helo=mx0a-001b2d01.pphosted.com) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1iHrH6-0000Ss-Tj for qemu-devel@nongnu.org; Tue, 08 Oct 2019 11:19:46 -0400 Received: from pps.filterd (m0098421.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.27/8.16.0.27) with SMTP id x98FDSFA070395 for ; Tue, 8 Oct 2019 11:19:41 -0400 Received: from e06smtp02.uk.ibm.com (e06smtp02.uk.ibm.com [195.75.94.98]) by mx0a-001b2d01.pphosted.com with ESMTP id 2vgvk294q2-1 (version=TLSv1.2 cipher=AES256-GCM-SHA384 bits=256 verify=NOT) for ; Tue, 08 Oct 2019 11:19:41 -0400 Received: from localhost by e06smtp02.uk.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Tue, 8 Oct 2019 16:19:39 +0100 Received: from b06avi18878370.portsmouth.uk.ibm.com (9.149.26.194) by e06smtp02.uk.ibm.com (192.168.101.132) with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted; (version=TLSv1/SSLv3 cipher=AES256-GCM-SHA384 bits=256/256) Tue, 8 Oct 2019 16:19:36 +0100 Received: from d06av26.portsmouth.uk.ibm.com (d06av26.portsmouth.uk.ibm.com [9.149.105.62]) by b06avi18878370.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id x98FJaft46334414 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 8 Oct 2019 15:19:36 GMT Received: from d06av26.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id E2816AE04D; Tue, 8 Oct 2019 15:19:35 +0000 (GMT) Received: from d06av26.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C40DBAE045; Tue, 8 Oct 2019 15:19:35 +0000 (GMT) Received: from smtp.tls.ibm.com (unknown [9.101.4.1]) by d06av26.portsmouth.uk.ibm.com (Postfix) with ESMTP; Tue, 8 Oct 2019 15:19:35 +0000 (GMT) Received: from bahia.tls.ibm.com (bahia.tls.ibm.com [9.101.4.41]) by smtp.tls.ibm.com (Postfix) with ESMTP id 8E45A2201ED; Tue, 8 Oct 2019 17:19:35 +0200 (CEST) From: Greg Kurz To: qemu-devel@nongnu.org Subject: [PULL 4/4] 9p: Treat multiple devices on one export as an error Date: Tue, 8 Oct 2019 17:19:25 +0200 X-Mailer: git-send-email 2.21.0 In-Reply-To: <20191008151925.1021706-1-groug@kaod.org> References: <20191008151925.1021706-1-groug@kaod.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 x-cbid: 19100815-0008-0000-0000-000003201E67 X-IBM-AV-DETECTION: SAVI=unused REMOTE=unused XFE=unused x-cbparentid: 19100815-0009-0000-0000-00004A3F2009 Message-Id: <20191008151925.1021706-5-groug@kaod.org> X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-10-08_06:, , signatures=0 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 malwarescore=0 suspectscore=1 phishscore=0 bulkscore=0 spamscore=0 clxscore=1034 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1908290000 definitions=main-1910080135 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [generic] [fuzzy] X-Received-From: 148.163.158.5 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Peter Maydell , Christian Schoenebeck , Greg Kurz , Antonios Motakis Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" Content-Type: text/plain; charset="utf-8" From: Antonios Motakis The QID path should uniquely identify a file. However, the inode of a file is currently used as the QID path, which on its own only uniquely identifies files within a device. Here we track the device hosting the 9pfs share, in order to prevent security issues with QID path collisions from other devices. We only print a warning for now but a subsequent patch will allow users to have finer control over the desired behaviour. Failing the I/O will be one the proposed behaviour, so we also change stat_to_qid() to return an error here in order to keep other patches simpler. Signed-off-by: Antonios Motakis [CS: - Assign dev_id to export root's device already in v9fs_device_realize_common(), not postponed in stat_to_qid(). - error_report_once() if more than one device was shared by export. - Return -ENODEV instead of -ENOSYS in stat_to_qid(). - Fixed typo in log comment. ] Signed-off-by: Christian Schoenebeck [groug, changed to warning, updated message and changelog] Signed-off-by: Greg Kurz --- hw/9pfs/9p.c | 70 +++++++++++++++++++++++++++++++++++++++++----------- hw/9pfs/9p.h | 1 + 2 files changed, 57 insertions(+), 14 deletions(-) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index ba1ab920f1eb..5a895ae0bbfe 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -573,10 +573,19 @@ static void coroutine_fn virtfs_reset(V9fsPDU *pdu) P9_STAT_MODE_SOCKET) =20 /* This is the algorithm from ufs in spfs */ -static void stat_to_qid(const struct stat *stbuf, V9fsQID *qidp) +static int stat_to_qid(V9fsPDU *pdu, const struct stat *stbuf, V9fsQID *qi= dp) { size_t size; =20 + if (pdu->s->dev_id !=3D stbuf->st_dev) { + warn_report_once( + "9p: Multiple devices detected in same VirtFS export, " + "which might lead to file ID collisions and severe " + "misbehaviours on guest! You should use a separate " + "export for each device shared from host." + ); + } + memset(&qidp->path, 0, sizeof(qidp->path)); size =3D MIN(sizeof(stbuf->st_ino), sizeof(qidp->path)); memcpy(&qidp->path, &stbuf->st_ino, size); @@ -588,6 +597,8 @@ static void stat_to_qid(const struct stat *stbuf, V9fsQ= ID *qidp) if (S_ISLNK(stbuf->st_mode)) { qidp->type |=3D P9_QID_TYPE_SYMLINK; } + + return 0; } =20 static int coroutine_fn fid_to_qid(V9fsPDU *pdu, V9fsFidState *fidp, @@ -600,7 +611,10 @@ static int coroutine_fn fid_to_qid(V9fsPDU *pdu, V9fsF= idState *fidp, if (err < 0) { return err; } - stat_to_qid(&stbuf, qidp); + err =3D stat_to_qid(pdu, &stbuf, qidp); + if (err < 0) { + return err; + } return 0; } =20 @@ -831,7 +845,10 @@ static int coroutine_fn stat_to_v9stat(V9fsPDU *pdu, V= 9fsPath *path, =20 memset(v9stat, 0, sizeof(*v9stat)); =20 - stat_to_qid(stbuf, &v9stat->qid); + err =3D stat_to_qid(pdu, stbuf, &v9stat->qid); + if (err < 0) { + return err; + } v9stat->mode =3D stat_to_v9mode(stbuf); v9stat->atime =3D stbuf->st_atime; v9stat->mtime =3D stbuf->st_mtime; @@ -892,7 +909,7 @@ static int coroutine_fn stat_to_v9stat(V9fsPDU *pdu, V9= fsPath *path, #define P9_STATS_ALL 0x00003fffULL /* Mask for All fields above = */ =20 =20 -static void stat_to_v9stat_dotl(V9fsState *s, const struct stat *stbuf, +static int stat_to_v9stat_dotl(V9fsPDU *pdu, const struct stat *stbuf, V9fsStatDotl *v9lstat) { memset(v9lstat, 0, sizeof(*v9lstat)); @@ -914,7 +931,7 @@ static void stat_to_v9stat_dotl(V9fsState *s, const str= uct stat *stbuf, /* Currently we only support BASIC fields in stat */ v9lstat->st_result_mask =3D P9_STATS_BASIC; =20 - stat_to_qid(stbuf, &v9lstat->qid); + return stat_to_qid(pdu, stbuf, &v9lstat->qid); } =20 static void print_sg(struct iovec *sg, int cnt) @@ -1116,7 +1133,6 @@ static void coroutine_fn v9fs_getattr(void *opaque) uint64_t request_mask; V9fsStatDotl v9stat_dotl; V9fsPDU *pdu =3D opaque; - V9fsState *s =3D pdu->s; =20 retval =3D pdu_unmarshal(pdu, offset, "dq", &fid, &request_mask); if (retval < 0) { @@ -1137,7 +1153,10 @@ static void coroutine_fn v9fs_getattr(void *opaque) if (retval < 0) { goto out; } - stat_to_v9stat_dotl(s, &stbuf, &v9stat_dotl); + retval =3D stat_to_v9stat_dotl(pdu, &stbuf, &v9stat_dotl); + if (retval < 0) { + goto out; + } =20 /* fill st_gen if requested and supported by underlying fs */ if (request_mask & P9_STATS_GEN) { @@ -1382,7 +1401,10 @@ static void coroutine_fn v9fs_walk(void *opaque) if (err < 0) { goto out; } - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } v9fs_path_copy(&dpath, &path); } memcpy(&qids[name_idx], &qid, sizeof(qid)); @@ -1484,7 +1506,10 @@ static void coroutine_fn v9fs_open(void *opaque) if (err < 0) { goto out; } - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } if (S_ISDIR(stbuf.st_mode)) { err =3D v9fs_co_opendir(pdu, fidp); if (err < 0) { @@ -1594,7 +1619,10 @@ static void coroutine_fn v9fs_lcreate(void *opaque) fidp->flags |=3D FID_NON_RECLAIMABLE; } iounit =3D get_iounit(pdu, &fidp->path); - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } err =3D pdu_marshal(pdu, offset, "Qd", &qid, iounit); if (err < 0) { goto out; @@ -2328,7 +2356,10 @@ static void coroutine_fn v9fs_create(void *opaque) } } iounit =3D get_iounit(pdu, &fidp->path); - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } err =3D pdu_marshal(pdu, offset, "Qd", &qid, iounit); if (err < 0) { goto out; @@ -2385,7 +2416,10 @@ static void coroutine_fn v9fs_symlink(void *opaque) if (err < 0) { goto out; } - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } err =3D pdu_marshal(pdu, offset, "Q", &qid); if (err < 0) { goto out; @@ -3065,7 +3099,10 @@ static void coroutine_fn v9fs_mknod(void *opaque) if (err < 0) { goto out; } - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } err =3D pdu_marshal(pdu, offset, "Q", &qid); if (err < 0) { goto out; @@ -3223,7 +3260,10 @@ static void coroutine_fn v9fs_mkdir(void *opaque) if (err < 0) { goto out; } - stat_to_qid(&stbuf, &qid); + err =3D stat_to_qid(pdu, &stbuf, &qid); + if (err < 0) { + goto out; + } err =3D pdu_marshal(pdu, offset, "Q", &qid); if (err < 0) { goto out; @@ -3634,6 +3674,8 @@ int v9fs_device_realize_common(V9fsState *s, const V9= fsTransport *t, goto out; } =20 + s->dev_id =3D stat.st_dev; + s->ctx.fst =3D &fse->fst; fsdev_throttle_init(s->ctx.fst); =20 diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 8883761b2c1d..5e316178d579 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -256,6 +256,7 @@ struct V9fsState Error *migration_blocker; V9fsConf fsconf; V9fsQID root_qid; + dev_t dev_id; }; =20 /* 9p2000.L open flags */ --=20 2.21.0